Skip to content

[FEATURE] GitHub Actions Security Scanner #68

Description

@mors119

Description

Analyze workflow files.

Detect:

curl | bash
wget | bash
chmod +x downloaded files

Also detect:

permissions: write-all

and excessive permissions.

Why

GitHub Actions is a major attack surface.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions